Hardware wallets are supposed to be the safest place to keep cryptocurrency, which is exactly why it matters when the company behind one finds and closes a hole before anyone can walk through it. BitBox, maker of the BitBox02 hardware wallet, has shipped firmware version 9.26.5, closing two serious vulnerabilities discovered in its own devices — and in doing so, it’s a useful case study in how the self-custody ecosystem is getting more resilient, not less.
What Was Actually Broken
The first flaw was a memory-corruption bug affecting unconfigured BitBox02 and BitBox02 Nova Multi-edition devices. In the worst case, a malicious host computer could have used it to run arbitrary code on the wallet and potentially push malicious firmware onto the device — the kind of attack chain that, left unpatched, could eventually put funds at risk.
The second issue lived inside BitBox’s implementation of Silent Payments, a privacy feature for Bitcoin that lets senders generate a fresh receiving address for every transaction without the recipient having to publish a new address each time. A flaw in that logic could have let a malicious host lock bitcoin to an address the owner never intended, opening the door to a ransom-style scenario where an attacker dangles the “correct” address in exchange for payment.
Why This Counts as Progress
Neither bug was exploited. BitBox says it has no reports of funds lost or of either flaw being used in the wild, and firmware 9.26.5 now ships with both issues fixed. That timing is the point: this is a vulnerability caught and patched before it became a headline about stolen funds, not after. It’s a meaningfully different story than the pattern that’s dogged the hardware wallet space recently, including a Coldcard firmware flaw linked to roughly $112 million in Bitcoin theft and separate data breaches affecting Trezor and SafePal customers.
Silent Payments itself is still a relatively new addition to Bitcoin’s privacy toolkit, and finding edge cases in a young feature is normal engineering work. What makes this a genuine improvement rather than just “another vulnerability disclosure” is that the fix hardens exactly the part of the wallet meant to make Bitcoin more private and more usable, without weakening its security guarantees in the process.
What Users Should Do
BitBox is recommending that every user update to firmware 9.26.5 as soon as possible. Hardware wallet firmware updates have historically seen inconsistent adoption — many users set a device up once and never touch the update prompt again — which means the real-world security benefit here depends on people actually installing the patch, not just on BitBox having shipped it.
For an industry built on the promise that self-custody is safer than trusting an exchange, stories like this one are a reminder that the promise only holds if the underlying hardware keeps getting more carefully audited, and if vendors keep disclosing and fixing what they find rather than staying quiet. This one checks both boxes.
Source: Cointelegraph, “BitBox Patches Code Execution and Bitcoin Lockup Flaws”

Leave a Reply